Security and data handling

Maybe you just typed your email into a chat on a company's website. Maybe you're deciding whether to put that chat on your own site. Either way, the question is the same: what happens to the data? The short version: Formidable collects a lead's name, email address and the answers to its customer's qualification questions. It researches the lead and personalises the conversation. The results are delivered to the customer whose website the lead used. Lead data is never sold and never used to train AI models. The full legal documents this page draws from are linked at the bottom.

At a glance

A summary of Formidable's data handling, one topic per row. Every row is explained in full further down the page.
TopicWhere we stand
What lead data is used forQualifying the lead and personalising the conversation. The results go to one place: the customer whose website the lead used.
AI trainingNever. Lead data does not train AI models.
Selling dataNever. Full stop.
Where data livesThe EU — a database in AWS Frankfurt (Neon), application hosting on Vercel's EU regions.
Encryption in transitTLS 1.2 or newer; database connections over SSL/TLS.
SubprocessorsSeven, all named on this page, with a 30-day objection window when the list changes.
Legal frameworkGDPR. An Article 28 Data Processing Agreement applies automatically with our Terms; EU Standard Contractual Clauses cover transfers outside the EEA.
Questionsdpo@formidable.work, or ask us anything at /support.

What does Formidable collect?

Formidable asks the lead for two things directly: their name and work email, in a short in-chat form. The customer's qualification questions are asked in the conversation itself, sometimes with answer buttons. The conversation is stored: the messages and their history.

Around that sits the context. To personalise the conversation, Formidable researches the lead; that research can add company information, job title, LinkedIn URL and work history from business-data providers. And the technical basics arrive with the chat, as they do on any website: IP address, browser type, timezone, locale and the page that referred the lead.

What we don't collect is just as deliberate. We don't intentionally process special categories of data, such as health or beliefs. We don't buy contact lists, and our acceptable use policy bans customers from using them. And the agent only talks to people who started a conversation on a customer's website.

And it isn't only lead data. Running the product means processing our customers' side too: account details, the connection tokens for the tools they plug in, and the chat histories themselves. The same rules on this page cover all of it.

Where does lead data go?

One place: the customer whose website the lead used. Everything the conversation produces is delivered there. When a lead books a meeting, their contact details, the booked meeting and a lead status are written into that customer's CRM. The qualification brief reaches that customer's sales team as briefing reports.

Customers can connect their own tools, such as a CRM or a calendar, using their own credentials. Those connections run under the customer's agreements with those services; we act as a technical intermediary. The rules on this page cover every integration Formidable offers.

And that really is the whole journey. Lead data isn't sold, and it isn't shared beyond the subprocessors listed below.

One scope note, because people ask: the free HubSpot diagnostic uses read-only access. It can look and report; it can't write changes to your HubSpot.

Where is lead data stored, and for how long?

In the EU. Lead and conversation data live in a database in AWS Frankfurt, eu-central-1, run by Neon, and the application runs in EU regions on Vercel. Data in transit is encrypted with TLS 1.2 or newer, database connections use SSL/TLS, and passwords are hashed with bcrypt.

How long we keep things depends on what the thing is:

  • When a customer's service ends, their data is deleted or returned, at the customer's choice.
  • When an account is deleted, its personal information is deleted within 30 days.
  • Cached research data on a lead is purged on request.
  • Analytics on formidable.work itself are first-party and cookieless, with IP addresses truncated and hashed; raw rows are pruned after 90 days.

Backups are automated, with point-in-time recovery.

Who can access lead data inside Formidable?

Access inside Formidable is role-based: internal systems restrict who can see what. API keys and secrets live in encrypted environment variables, never in source code. Data access is logged and monitored, and access logs and security events are reviewed regularly. These commitments come from the same place as the encryption facts above: Annex II of our Data Processing Agreement, the security measures we're contractually held to.

Who processes lead data on our behalf?

Nobody runs a product like this alone, and we'd rather name names than gesture at "trusted partners". We use subprocessors to run the product. They're listed in our Data Processing Agreement, and customers get a 30-day objection window when the list changes. The list today, in full:

  • OpenAI, which runs the AI conversation. Processing located in the EU.
  • Neon, the database. EU hosting in AWS Frankfurt; US company.
  • Vercel, application hosting. EU hosting; US company.
  • Google, sign-in and bot protection. US.
  • Resend, transactional email, including lead briefing reports. US.
  • People Data Labs, B2B contact and company research. US.
  • n8n, workflow automation. Germany.

Where a subprocessor sits outside the EEA, transfers run under the EU Standard Contractual Clauses.

What does Formidable never do?

We never sell lead data. We never use lead data to train AI models. We never contact a lead outside the on-site conversation; any follow-up comes from the customer's own team. And we never buy contact lists; we ban our customers from messaging purchased lists through us, too. This section is short because "never" doesn't need qualifying.

What do we secure, and what does the customer own?

Security is a shared job, so here is the split. We secure the service: the application, the database, and the subprocessor relationships above. Our customers own their side: the tools they connect run under their own agreements with those services, and rights requests from leads route through them, with our help. And nobody has to take our word for any of it — the Data Processing Agreement gives every customer the right to ask us to demonstrate compliance, audits included.

Your rights, and where we stand under GDPR

Formidable is built and run by Verbose OÜ, registry code 17089033, registered in Tallinn, Estonia. We operate under GDPR.

GDPR assigns two roles, and here they split cleanly. When a lead talks to a customer's agent, the customer is the controller and Verbose OÜ is the processor: rights requests about those conversations, such as access, correction or deletion, go to the company whose website was used, and we assist that company in answering them. For visitors to formidable.work and holders of a Formidable account, Verbose OÜ is the controller, and the Privacy Policy sets out your rights: access, correction, deletion and portability.

Our Data Processing Agreement follows Article 28 GDPR, incorporates the EU Standard Contractual Clauses, and applies automatically when a customer accepts the Terms of Service; nobody has to remember to sign anything. If a breach affects personal data, we notify the affected customer without undue delay, with a 72-hour notification target.

This page is the readable account. Read the full documents: the Data Processing Agreement and the Privacy Policy. The plain-language version of who we are, and what happens with data, is on the company page.

Questions

Ask us anything. For data protection, write to dpo@formidable.work - security questions go there too, until a dedicated security address exists. If we got something wrong on this page, tell us; we would rather correct it than defend it.